Toffee Moon Limited ("We", “Us” and “Our”) are committed to the protection of your privacy at all times. We want you to know that we would never share your data with other companies and businesses for marketing purposes. In this Privacy Notice, we’ve provided information on when and why we collect your personal information, how we use it and what you should do if you have any concerns.
We will collect, store, use and disclose Personal Data in accordance with all applicable laws relating to the protection of Personal Data.
The information we collect and how we use it:
In order to fulfil your order and any future customer service requests, we need to know certain personal data collected at the time of order. The information we hold will consist of but not be limited to the following: Title; Name; Address; Mailing Preference flags such as ‘Do not mail’; Products purchased from us in the past, including their cost; Telephone number, if offered to us (this will only be used for matters relating to your order); Email address; Where we believe you heard about us from. Credit card details are encrypted after data entry and are not stored on our systems after use. We do not collect any Special Category Data (sensitive data) such as race, religion, biometrics or health data. It is our policy that your information is private and confidential. Accordingly, the personal information you provide to us is stored in a secure location, and is accessible only by designated staff. We also collect data because it is necessary for the pursuit of our legitimate interests. Our legitimate interests are set out below:
Understanding our customers’ wishes and shopping preferences
Improving our service and our products
How we use your information for Direct Marketing & how to manage your marketing preferences
1) Marketing by us, Toffee Moon Limited.
When you choose not to opt out of 1st party marketing, we may collect your email address, name and order details so that we can tailor our communications with you and send you relevant offers and news via email. If at any time you wish to opt out of receiving emails, email us at . We also advertise on digital platforms, such as Facebook, Google and Instagram. We use these platforms to reach you and people like you with relevant, targeted offers and updates from Toffee Moon. To turn off targeted ads on any of these platforms, please see the individual privacy settings for each.
2) Marketing by other companies
We do not share any information with 3rd parties for the purpose of marketing.
How we use your information to understand our customers’ wishes and shopping preferences
Our communications are designed to tell you about the benefits we can offer so that you have access to our best deals. We use the information we have about you to tailor the content and try to ensure that the offers are as relevant to you as possible. Under the Data Protection Legislation, this might qualify as profiling. If you do not wish us to use your data for this purpose, please email us at .
We work with the following data processors in order to carry out our marketing activities. From time to time we may use other legally compliant data processors as required. These processors will hold data for no longer than is required to complete the analysis before securely deleting it. All data is only accessible to select, authorised individuals.
We use a third-party provider, Ascend by Wix, to deliver our newsletter. We gather statistics around email opening and clicks using industry standard technologies to help us monitor and improve our e-newsletter. For more information, please see Wix’s privacy notice () You can unsubscribe to mailings at any time by clicking the unsubscribe link at the bottom of any of our emails or by emailing us at
The website is hosted on the Wix.com platform. Wix.com provides us with the on-line platform that allows us to sell our products and services to you. Your data may be stored through Wix.com’s data storage, databases and the general Wix.com applications. They store your data on secure servers behind a firewall.
All direct payment gateways offered by Wix.com and used by our company adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. Any payment transactions will be encrypted using SSL technology.
Facebook: If you do not wish to see targeted ads on Facebook, you can update your preferences on Facebook by clicking on the Ads section within Settings on Facebook. Facebook matches email address, marketing preferences and purchase history for the purpose of audience selection for our advertising campaigns on Facebook and Instagram.
Google Ads: They match your email address, marketing preferences and purchase history for the purpose of audience selection for our advertising campaigns on Google Search and Display Networks. For information on how Google ensures GDPR and other data protection law compliance, see here:
Twitter, and Instagram: They match your email address, marketing preferences and purchase history for the purpose of audience selection for our advertising campaigns on their respective platforms.
How long we keep your data
To serve our customers in the best possible manner and to continue to inform you about new products and services, we retain customer data for seven years after the last purchase date, or until you exercise your right to deletion as described below in the YOUR RIGHTS section.
You retain at all times the right to access or amend or delete any Personal Data we hold about you or to exercise your right of data portability or to object to, or restrict, the purposes for which your Personal Data is processed on certain grounds. You may also modify your marketing preferences at any time by emailing us at . You may exercise this right by making a request in accordance with Data Protection Laws, by emailing .
You have the right to access your information
You retain the right to access information held about you. Your right of access can be exercised by making a request to us verbally or in writing. We will deal with your request and provide details of the information we hold about you within 28 day.
You have the right to lodge a complaint
If you are not satisfied with the service we provide with regard to the protection of your Data you are entitled to contact the Information Commissioner’s Office Helpline: 0303 123 1113.
You have the right to ask us what personal data we hold about you.
You have the right to ask us to update or amend any out-of-date or incorrect data.
If at any time you wish to amend your data, you can email us at . To protect your privacy and security we may need to verify your identity before making amendments. If you wish to update your marketing preferences at any time, you email us at
You have the right to ask us to delete the data we hold about you.
We will seek to act in the best interests of our customers and will not abuse our position of data controller. We wish to be as clear and transparent as possible and uphold any requests for data disclosure or amendment as soon as possible. Due to the nature of data, when an amendment is made to data it may take up to two weeks for it to become effective, although we will do everything possible to ensure this time delay is kept to a minimum.
IP Addresses and Cookies.
We may use your IP address to help diagnose problems with its server, and to administer the Site. Your IP address is used to help identify you and to gather broad demographic information. IP addresses are also used to provide an audit trail in the case of any attempted illegal or unauthorized use of the Site.
There are four main types of cookies – here’s how and why we use them.
(1) Site functionality cookies – these cookies allow you to navigate the website and use our features, such as “Add to Bag”.
(2) Site analytics cookies – these cookies allow us to measure and analyse how our customers use the site, to improve both its functionality and your shopping experience.
(3) Customer preference cookies – when you are browsing or shopping on Toffee Moon, these cookies will remember your preferences (like your language or location), so we can make your shopping experience as seamless as possible, and more personal to you.
(4) Targeting or advertising cookies – these cookies are used to deliver ads relevant to you. They also limit the number of times that you see an ad and help us measure the effectiveness of our marketing campaigns.
Before we place any Cookies on your computer or device, you will be presented with a pop-up message requesting your consent to set those Cookies. However, you may, if you wish, deny consent to the placing of Cookies; although please be aware that certain features of the Website may not function fully or as intended.
When someone visits we use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of those visiting our website.
By using our site, you agree to us placing these sorts of cookies on your device and accessing them when you visit the site in the future. If you want to delete any cookies that are already on your computer, the “help” section in your browser should provide instructions on how to locate the file or directory that stores cookies. Further information about cookies can be found at . Please note that by deleting or disabling future cookies, your user experience may be affected and you might not be able to take advantage of certain functions of our site.
Links To Other Websites
Our site may at times, contain links to and from other websites, including social media. If you follow a link to any of these websites, please note that these websites have their own privacy notices and that we do not accept any responsibility or liability for these notices. Please check these notices carefully before you submit any personal data to these websites
Changes to This Privacy Notice
For the purpose of this Privacy Notice the Data Controller is Elaine Smyth at Toffee Moon Limited, 9 Holmwood Road Didsbury Manchester M20 3JY.